Filter
Exclude
Time range
-
Near
PRODAFT CATALYST Explore CATALYST by PRODAFT, a cyber threat intelligence platform for tracking threat actors, analyzing cybercrime activity, and delivering real-time, actionable security insights. Turn intelligence into actionโ€”and stay ahead of evolving threats. #Cybersecurity #ThreatIntel #CyberResilience #VistemElevate catalyst.prodaft.com/public/โ€ฆ

17
Intel Report [CRITICAL] - The Gentlemen ransomware operation, tracked as Phantom Mantis by PRODAFT and Storm-2697 by Microsoft, has rapidly evolved from a RaaS affiliate into an independent and highly capable ransomware partnership program. Led by... enigma-global.com/og/report/โ€ฆ
32
๐Ÿ•ต๏ธโ€โ™‚๏ธ ุณู‚ูˆุท ู‚ู†ุงุน "The Gentlemen" ุงู„ู…ู„ู ุงู„ุงุณุชุฎุจุงุฑุงุชูŠ ูˆุงู„ุชูƒุชูŠูƒ ุงู„ุชู‚ู†ูŠ ู„ุฃุฎุทุฑ ุนุตุงุจุงุช ุงู„ูุฏูŠุฉ ุงู„ู…ุฏุนูˆู…ุฉ ุจุงู„ุฐูƒุงุก ุงู„ุงุตุทู†ุงุนูŠ ๐Ÿงฌ๐Ÿ”’ ูƒุดู ุชู‚ุฑูŠุฑ ู…ุคุณุณุฉ PRODAFT ุนู† ุงู„ู‡ูˆูŠุฉ ุงู„ุญู‚ูŠู‚ูŠุฉ ู„ู‚ุงุฆุฏ ุงู„ู…ุฌู…ูˆุนุฉ ูˆู‡ูˆ ุงู„ุฑูˆุณูŠ "ุฃู„ูƒุณู†ุฏุฑ ูŠุงุจุงูŠูŠู" (ุงู„ู…ุนุฑูˆู ุจู€ LARVA-368) ุงู„ู…ุฌู…ูˆุนุฉ ุจุฏุฃุช ูƒุดุฑูŠูƒ ู„ุนุตุงุจุงุช ุนู…ู„ุงู‚ุฉ ู…ุซู„ LockBit ูˆ Qilin ู‚ุจู„ ุฃู† ุชู†ูุตู„ ูˆุชุชุญูˆู„ ู„ุจุฑู†ุงู…ุฌ ู…ุณุชู‚ู„ ูˆู…ูƒุชูู ุฐุงุชูŠุงู‹ โš™๏ธ ุงู„ุชูƒุชูŠูƒ ุงู„ุชู‚ู†ูŠ ุงู„ู…ุฑุนุจ ูˆุงู„ุขุซุงุฑ : ๐Ÿง  ุงู„ุฐูƒุงุก ุงู„ุงุตุทู†ุงุนูŠ : ุชุนุชู…ุฏ ุงู„ู…ุฌู…ูˆุนุฉ ุจุดูƒู„ ุถุฎู… ุนู„ู‰ ุงู„ู€ AI ู„ุชุทูˆูŠุฑ ูˆุตูŠุงู†ุฉ ุจุฑู…ุฌูŠุงุช ุงู„ุชุดููŠุฑ ูˆุฃุชู…ุชุฉ ุงู„ุงุฎุชุฑุงู‚ ๐Ÿงฌ ุฏูˆุฏุฉ ุฐุงุชูŠุฉ ุงู„ุงู†ุชุดุงุฑ : ุงู„ุจุฑู…ุฌูŠุฉ ู…ูƒุชูˆุจุฉ ุจู„ุบุฉ GoุŒ ูˆุจู…ุฌุฑุฏ ุชูุนูŠู„ ุฃู…ุฑ โ --spreadโ  ุชุชุญูˆู„ ุฅู„ู‰ ุฏูˆุฏุฉ ุชุดูุฑ ูƒู„ ู†ุธุงู… ู…ุชุงุญ ุนู„ู‰ ุงู„ุดุจูƒุฉ ุชู„ู‚ุงุฆูŠุงู‹ ู…ุน ุฎูŠุงุฑ โ --wipeโ  ู„ุญุฐู ุฃูŠ ู…ู„ู ู‚ุงุจู„ ู„ู„ุงุณุชุฑุฏุงุฏ ๐Ÿšช ุงู„ูˆุตูˆู„ ุงู„ุฃูˆู„ูŠ : ุงุณุชุบู„ุงู„ ุงู„ุฃุฌู‡ุฒุฉ ุงู„ู…ูˆุงุฌู‡ุฉ ู„ู„ุฅู†ุชุฑู†ุช (ู…ุซู„ ุฌุฏุฑุงู† ุญู…ุงูŠุฉ Cisco ูˆ Fortinet) ู…ุน ุชูƒุชูŠูƒ ุงู„ุงุจุชุฒุงุฒ ู…ุชุนุฏุฏ ุงู„ู‚ู†ูˆุงุช (ุชุดููŠุฑุŒุฅูŠู…ูŠู„ุงุชุŒ ูˆุถุบุท ุนุจุฑ ุงู„ู‡ุงุชู) ๐Ÿ’ก ุงู„ุฎู„ุงุตุฉ : ุงู„ู…ุฌู…ูˆุนุฉ ุชุณุชุญูˆุฐ ุญุงู„ูŠุงู‹ ุนู„ู‰ 10% ู…ู† ุฅุฌู…ุงู„ูŠ ุนู…ู„ูŠุงุช ุจุฑุงู…ุฌ ุงู„ูุฏูŠุฉ ุนุงู„ู…ูŠุงู‹ ูˆุชุณุชู‡ุฏู ุจุดูƒู„ ุฎุงุต ุจูŠุฆุงุช VMware ูˆ Active Directory ุนุจุฑ ู†ู…ูˆุฐุฌ ุชู‚ุงุณู… ุฃุฑุจุงุญ ุนุฏูˆุงู†ูŠ (90% ู„ู„ุดุฑูƒุงุก) ู„ุฌุฐุจ ู…ุญุชุฑููŠ ุงู„ุงุฎุชุฑุงู‚ ๐Ÿ”’๐Ÿ“‰ #ุงู„ุฃู…ู†_ุงู„ุณูŠุจุฑุงู†ูŠ #TheGentlemen #Cybersecurity
1
80
ege retweeted
Jun 10
๐Ÿšจ PHANTOM MANTIS (a.k.a. The Gentlemen): They only hold the door open to exfiltrate your data. Meet Phantom Mantis, the ransomware crew that went from total unknown to one of the most prolific operations. ๐Ÿ’€ ๐Ÿ”ฅ HUNDREDS of victims on their leak site ๐ŸŒ Confirmed hits across 20 countries ๐Ÿ“ˆ Explosive growth that nobody saw coming We are tearing the operation wide open.๐Ÿ•ต๏ธ ๐Ÿ”ด TLP:RED version: the full deep-dive: affiliate intel, victimology, the usual PRODAFT stuff. โšช TLP:CLEAR: Open to everyone, right here: ๐Ÿ‘‰ catalyst.prodaft.com/public/โ€ฆ #TheGentlemen
5
14
748
Wake up. An email from a vendor recently argued that a SQL injection vulnerability in their database backup CLI was merely "informational" because: "If an attacker can create a table with a malicious name, they already have access." The response also stated: "We do not consider the CLI to be suitable for machine usage and do not use it for internal workflows." There are two fundamental problems with this reasoning. First, the threat model assumes only the workflows the vendor personally envisions. There are SaaS n-tier designs where users actually create datasets, workspaces, projects, import jobs, tenant-specific resources, temporary analysis tables, plugin-defined objects, and many other entities that eventually become database object names. User-controlled object names are not an edge case. Second, the threat model ignores how customers actually operate systems. DevOps teams use CLI tools for automation every day. Backups, restores, migrations, exports, CI/CD jobs, disaster recovery procedures, and offsite archival processes are frequently driven by platform CLIs. Whether the vendor uses the CLI internally is largely irrelevant. Customers do. The security question is not whether an attacker can create a table. The security question is whether attacker-controlled metadata can be processed later by a different trust boundary: an administrator, a service account, a backup pipeline, a CI runner, or an automated operational workflow. As a platform provider, your threat model cannot stop at your own assumptions about how customers should use your product. (Oh by the way, yes we have these both use-cases at PRODAFT :)
1
1
31
5,361
Conclusion 25/25 Subtle Snail exemplifies the subtle, persistent nature of cyber operations that continue alongside more visible conflicts. By shining a light on these activities, we gain a fuller picture of global strategic dynamics. Stay informed, remain cautious online, and recognise that much of todayโ€™s power plays happen quietly in the digital shadows. For an in depth report on this check out @PRODAFT and the link below catalyst.prodaft.com/public/โ€ฆ

2
180
Replying to @loop0420 @mdisec
LOL. He is a manager at prodaft, so he should have more confidence than you. Actually, all skids have the confidence to say that, just like you
1
2
125
secp0 Ransomware has allegedly breached IT and cybersecurity firm Terralogic or rehashing last years breach New URLs /secp0-news[.]ws /secp0-leaks[.]com /secp0-support[.]cfd cc @PRODAFT
New Secp0 Ransomware leak site Ransom for vulnerabilities otherwise exploit is disclosed h/t @PRODAFT /secp0-news[.]net - 185.178.46[.]228 /secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd[.]onion
5
19
4,721
> phish blackhats on cybercrime forums for account takeover > sell compromised forum accounts to prodaft for profit > only get swatted twice > profit?
1
39
2,963
Replying to @IntelOpsV3
nice honeypot @PRODAFT
3
270
Replying to @club31337
Most obvious ProDaft honeypot ๐Ÿ˜‚
1
1
1
540
Replying to @PRODAFT
Blue on blue all day long. Glad not to be there ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

ALT Spider Man GIF

2
158